Privacy Policy

Effective . Last updated .

At a glance

What we collect
Your account information, the files you upload, the audiences we generate for you, and basic operational logs.
Where it goes
Encrypted storage and compute on Amazon Web Services. Aggregate (never row-level) profile summaries sent to Anthropic for narrative generation.
Who else touches it
AWS, Anthropic, and EmailOversight (only when you ask us to verify deliverability). Nobody else.
How to reach us
hello@tessera.ai

1. About this policy

This Privacy Policy describes how Tessera AI, LLC, a [STATE] limited liability company ("Tessera," "we," "us"), collects, uses, and discloses information when our business customers use the Tessera platform at tessera.ai (the "Service").

Tessera is a business-to-business audience intelligence platform. Our direct customers are publishers, marketers, and agencies who contract with us under a master service agreement. This policy is written for those customers and for the legal teams that review them.

If you are a consumer whose email address appears in our identity database because you opted in to a marketing relationship with one of our data partners, please contact us at hello@tessera.ai to exercise your rights of access, correction, or deletion.

2. Information we collect

2.1 Account information

When you are granted access to Tessera under a master service agreement, we record your work email address, your name and job title (if provided), the company you represent, and an authentication credential. We use this information to identify you, authenticate your sessions, and communicate with you about the Service.

2.2 Customer-uploaded data

The Service lets you upload files containing email addresses (either in plaintext or as MD5 hashes). Depending on the job type, these files represent your subscriber list, your CRM customers, a paid-converter cohort, or a lapsed-customer list. We treat the contents of these files as your confidential information.

Uploaded files are stored on encrypted Amazon S3 storage under an access-controlled path scoped to your tenant. We retain uploaded files as specified in your applicable master service agreement.

2.3 Generated outputs

For each audience job you run, the Service produces an output file (typically a CSV) containing matched and enriched records, plus an AI-generated narrative summary. Output files contain identity attributes drawn from our licensed identity database; they may include plaintext email addresses, names, mailing addresses, demographic attributes, interests, and engagement metrics.

Output files are stored alongside the corresponding upload under the same access-controlled path and are retained as specified in your applicable master service agreement.

2.4 Cookies and session data

We set a single session cookie to keep you signed in. The cookie is short-lived (up to seven days) and contains no advertising or analytics identifiers. We do not run third-party analytics, tracking pixels, or behavioral advertising on the Service.

2.5 Server logs

We record routine operational metadata for each job: a job identifier, timestamps, row counts, the requesting user, and any error traces. Logs do not contain the contents of your uploaded files or generated outputs.

3. Sources of the identity data we match against

The identity database against which your uploads are matched is licensed from a third-party identity-resolution partner. Our partner sources its identity records from opted-in consumer marketing relationships and maintains its own consumer-facing privacy practices, including consumer rights to access, correct, and delete records.

If a consumer asks us to remove their record from the database, we forward the request to our data partner, who is the controller of that record. We can also block the consumer's email address from appearing in any future Tessera output produced for our customers.

4. How we use information

We use the information described above to:

  • Provide the Service, including matching your uploads against the licensed identity database, enriching records with the attributes available, scoring engagement, and generating output files.
  • Authenticate your sessions and maintain account security.
  • Operate, monitor, and improve our infrastructure.
  • Communicate with you about the Service, including support requests and changes to this policy.
  • Comply with our legal obligations and respond to valid legal process.

What we do not do: we do not sell your customer-uploaded data, we do not share it with any other Tessera customer, we do not use it to enrich any other customer's audience, and we do not use it to train our or any third party's machine-learning models.

5. Third-party data processors

We rely on a small set of carefully selected service providers to deliver the Service. Each provider processes data only on our instructions and only for the purposes described below.

Amazon Web Services (AWS)
Hosts the Tessera application, stores uploaded files and outputs in encrypted S3 storage, and runs all data-matching queries via Athena. All processing occurs in AWS US regions.
Anthropic
Generates the narrative profile summary that accompanies each audience report. We send Anthropic only aggregate, non-identifying audience statistics (such as median age, top interest categories, ISP distribution). We never send raw rows, plaintext email addresses, or any personally identifying value.
EmailOversight
Performs optional deliverability verification on output rows when you explicitly request it. EmailOversight receives the email addresses from the specific output file you elect to verify, and nothing else.

6. Data sharing and disclosure

We do not sell customer-uploaded data or generated outputs. We do not share customer data with any other Tessera customer. We disclose data only:

  • To the third-party processors listed in Section 5, for the purposes stated.
  • In response to valid legal process (subpoena, court order, lawful government request), to the extent legally required.
  • To enforce our agreements or protect our or others' rights, property, or safety.
  • In connection with a corporate transaction (merger, acquisition, financing), under customary confidentiality protections.
  • With your written instruction.

We may publish aggregate, de-identified statistics about the Service (for example, total identities matched, average match rate) for marketing or research. These statistics are not linkable to any individual customer or end consumer.

7. Retention

We retain customer-uploaded files and generated outputs as specified in your applicable master service agreement. For customers without a fixed retention schedule in their agreement, we retain those files for the duration of the contract term and a reasonable post-termination wind-down period.

Account information is retained while your account is active and for a reasonable period afterward to support audit, billing, and legal-hold requirements. Operational logs are retained on standard infrastructure timelines.

You may request earlier deletion at any time by contacting hello@tessera.ai.

8. Your rights

Depending on where you reside, you may have rights to access, correct, delete, or restrict the use of personal information we hold about you. These rights include those provided by the California Consumer Privacy Act (CCPA) and comparable state laws.

For customer-uploaded data, Tessera acts as a service provider on your behalf. Requests from end consumers regarding their inclusion in your customer-uploaded data should be directed to you; we will assist you in fulfilling such requests as specified in your master service agreement.

For records that exist in our licensed identity database independent of any customer upload, contact us at hello@tessera.ai and we will coordinate with our data partner to honor your request.

We do not sell personal information as that term is defined under CCPA. We do not knowingly process the personal information of California residents under 16 without consent.

9. Security

We protect customer data with a layered set of controls: TLS encryption for data in transit, server-side encryption for data at rest in AWS S3, IAM-scoped access to compute and storage, tenant-scoped file paths, session-based authentication with short-lived cookies, and audit logging of administrative actions.

Tessera is not currently SOC 2 or ISO 27001 certified. We will update this policy if and when that changes.

No system is perfectly secure. If we discover a security incident affecting customer data, we will notify affected customers without undue delay and in accordance with applicable law.

10. International data transfers

The Service is operated from the United States and intended for use by US-based business customers. We do not currently market to or knowingly process the personal information of residents of the European Economic Area, the United Kingdom, or Switzerland.

If you are based outside the United States and choose to use the Service, you understand that your information will be processed in the United States, which may have different data-protection laws than your country of residence.

11. Children's privacy

The Service is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, contact us and we will delete it.

12. Changes to this policy

We may update this policy from time to time. If we make material changes, we will notify active customers by email and update the "Last updated" date above. Continued use of the Service after a material update constitutes acceptance of the revised policy.

13. Contact

Questions about this policy, requests to exercise privacy rights, and other privacy matters can be addressed to:

hello@tessera.ai
Tessera AI, LLC

© 2026 Tessera AI, LLC. All rights reserved.